1,721,537 research outputs found
InnoDB Datenbank Forensik Rekonstruktion von Abfragen über Datenbank-interne Logfiles
Datenbanksysteme werden in der digitalen Forensik oft vernachlässigt, hinterlassen aber durch Transaktionen an vielen Stellen (temporäre) Spuren. Jede Transaktion kann - sofern unterstützt - rückgängig gemacht werden (rollback). InnoDB, eine populäre MySQL-Storage-Engine, erzeugt hierfür eigene Log-Dateien. In dieser Ar- beit dekodieren wir diese internen Log-Files von InnoDB, um die ausgeführten Datenbankabfragen zu rekonstruieren, welche Daten verändert haben. Abschließend gehen wir noch auf die Zusammenhänge zwischen der internen Datenspeicherung und den Log-Dateien ein
Sharing and reusing learning designs: Contextualising enablers and barriers
Reusing learning designs created by successful teachers is a means of sharing innovation and best practice whilst at the same time conserving resources. It would seem beneficial therefore to encourage and promote this practice. Repositories exist to support reuse and the sharing of exemplary learning objects and learning designs, however, there is little evidence of widespread adoption by teachers and pre-service teachers. This paper discusses the development of an environment conducive to sharing and reuse created in a pre-service teacher education course over a two-year period. Issues of pedagogy and the perspective of staff and students in this context are discussed
Web-based Industry Partner Portals to University Workplace Learning Programs: Implementation and Design Issues
With increasing emphasis from universities on workplace learning programs in which students undertake industry placements as part of their degrees, there is a need for disciplines without a tradition of workplace learning to engage with potential industry partners. A key way to address this need is for universities to design web-based portals through which industry partners can engage with these programs. To build industry-university partnerships successfully, industry portals must: be easy for industry partners to find online, and facilitate efficient communication between industry partners and university workplace learning staff and students. Integration with university web systems and governance frameworks can lead to delays in the launch of a web-based industry partner portal. This paper focuses on the early stages of the design and implementation of Queensland University of Technology’s Creative Industries Industry Portal as a case study of a new development in web-based university-industry engagement
Webserver-security and virtualization
Beinah im Wochentakt berichten die Medien von Hackerangriffen auf Webseiten. Selbst Konzerne wie Sony, Banken (Citigroup) und Kreditkartenunternehmen (Mastercard) sind betroffen. Motiviert durch ein aktuelles Softwareprojekt des Autors zeigt diese Arbeit welche aktuellen Angriffe und Best-Practice-Gegenmaßnahmen Webserver und Webseiten betreffend derzeit existieren. Zusätzlich wird auf die Sicherheitsaspekte von Hosting, Virtualisierung und Cloud-Computing eingegangen. Die Ergebnisse wurden in die Ebenen Netzwerk, Betriebssystem, Dienste, Webanwendung kategorisiert und stammen aus Experten-Interviews, Case-Studies, veröffentlichten Schwachstellen, bekannten Angriffen auf Unternehmen, Gegenüberstellungen von Sicherheitslösungen, durchgeführten Experimenten in einem virtuellen Labor und einer ausführlichen Literaturstudie. Im Rahmen dieser Arbeiten wurden Schwachstellen (Fakultät für Informatik der TU-Wien, Ruby on Rails) aufgedeckt, anhand von Proof-Of-Concept-Code belegt und mittels aufgezeichneten Screencasts dokumentiert.Nearly every week attacks on websites are reported by the media. Even transnational corporations like Sony, banks (Citigroup) or credit card companies are affected. Motivated by a recent software project, the author of this paper shows current attacks and best-practice-countermeasures concerning webservers and websites.Furthermore the security aspects of hosting, virtualization and cloud-computing are shown. The results were categorized in network, operating system, services and webapplication and were deduced through expert-interviews, case studies, published vulnerabilities, publicly known attacks on companies, comparison of security-solutions, experiments executed in a virtual labor and a detailed study of literature. In the context of this paper there have been discovered vulnerabilities (faculty of informatics of the TU-Vienna, Ruby on Rails), which are proven by proof-of-concept-exploits and documented by recorded screencasts
Going Beyond Counting First Authors in Author Co-citation Analysis
The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation
counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings
are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that
only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into
account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed
Estimating Security in Open Source Web Applications
Viele kleine und mittelständische Unternehmen außerhalb des EDV-Sektors beschäftigen oft nur eine Person, die für "die EDV" zuständig ist. Vorgesetzte teilen ihr daher vielfältige Aufgaben zu, wie beispielsweise die Erstellung einer Firmenwebseite. Da Kostenersparnis hinter solchen Aufträgen steht, erhält sie kein Budget für Ausgaben. Folglich sind kostenlose Open Source Lösungen unter den wenigen verbleibenden Alternativen. Sicherheitsprüfung von Software ist ein komplexes Themengebiet. Will sich eine EDV-bedienstete Person ohne Erfahrung mit Sicherheitsprüfungen aufgrund von Sicherheitseigenschaften zwischen zwei Open Source Webanwendungen entscheiden, benötigt sie dafür geeignete Werkzeuge. Leider gibt es keine kostenlos verfügbaren Werkzeuge, die alle Anforderungen einer solchen Person erfüllen. Artikel über die Sicherheit von Webanwendungen, die im Internet veröffentlicht werden, unterliegen oftmals voreingenommenen Ansichten der Autoren oder sind für Personen ohne Erfahrung unverständlich verfasst. Folglich stellt eine Sicherheitsprüfung von Webanwendungen eine Herausforderung dar. Diese Arbeit stellt eine Methode vor, welche es EDV-Bediensteten ermöglicht, von mehreren Alternativen die als am sichersten einzuschätzende Webanwendung zu wählen. Die im Vorfeld ausgewählten Produkte entsprechen den Firmenrichtlinien und die Person beherrscht die Grundlagen der Webentwicklung in der relevanten Programmiersprache und Technologie. Die Methode gliedert die vorgeschlagene Untersuchung der Sicherheit in nachvollziehbare Teilaufgaben und nutzt die zur Verfügung stehenden, kontextuellen Informationen der prüfenden Person. Zudem priorisiert sie die Aufgaben nach dem Kosten/Nutzen-Prinzip, um effektivste Zeitnutzung zu gewährleisten. Informatikstudenten, die nicht auf Web-Sicherheit spezialisiert sind, haben eine funktionsfähige Implementierung dieser Methode getestet. Sie haben in etwa den selben Wissensstand im Bezug auf Web-Sicherheit wie jene EDV-Bediensteten, von denen diese Arbeit ausgeht. Die erlangten Ergebnisse deuten darauf hin, dass die Methode und ihre Implementierung für die Untersuchung und den Vergleich von Open Source Webanwendungen im Bezug auf ihre Sicherheitseigenschaften gut geeignet ist. Die akkurate Arbeitsweise der untersuchenden Person spielt dabei eine große Rolle für die Qualität der Ergebnisse. Die erweiterbare Implementierung erleichtert die kontinuierliche Verbesserung der Methode.Many small and medium-sized companies outside the Information Technology (IT) sector employ a person responsible for IT -in general-. Supervisors commission such IT individuals with a variety of tasks, such as, creating a company website. Given that cost considerations often result in such assignments, management allocates no budget for expenses. This leaves free open source web applications as one of the rare alternatives. Security evaluation is a complex field of expertise. There are no freely available tools that cover all the requirements of an IT individual without security experience to choose between open source web applications. Security appraisal on the Internet is exposed to author bias, or it is not understandable to an average IT professional. Consequently, a security-based decision for a web application is difficult to make. This work proposes a method, called EstSecure, that supports IT professionals in finding such a security-based choice. It helps them determine the estimably most secure web application from a preselected set of candidates. It is assumed that the IT professional has basic web development knowledge. Then, EstSecure divides the security evaluation into manageable tasks, leverages user-provided context information, and ranks the tasks based on a cost-benefit ratio to achieve maximum time efficiency for the user. IT students not focused on IT security tested the proposed method using its implementation. The students have approximately the same security knowledge as the assumed IT professionals. The results indicate that EstSecure and its implementation are suitable for evaluating and comparing open source web application security properties. They further imply that the rigor of the user is essential for the success of EstSecure. Extensible implementation will allow future work to further improve the method and continuously optimize its utility
Variations on the Author
“Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship
Appropriate Similarity Measures for Author Cocitation Analysis
We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis
- …
